Hackers obtain counterfeit TLS certificates for Google and other large services

by | Oct 10, 2026 | Technology

Hackers obtain counterfeit TLS certificates for Google and other large services

Hackers gained control of the .gh, .sl, and .as country-code top-level domains and leveraged this access to mint fraudulent TLS certificates for Google and several other major global organizations, Google disclosed Tuesday. By manipulating authoritative DNS records within these domains, the attackers were able to satisfy automated validation procedures required by certificate authorities to issue the credentials.

TLS certificates serve as the cryptographic foundation for securing websites, email servers, and other internet services. These digital credentials bind domain names to public encryption keys, allowing users to verify they are connecting to legitimate services rather than malicious imposters. Access to unauthorized certificates enables attackers to impersonate targeted infrastructure and intercept communications.

Google did not publicly identify which of its specific domains were affected or name the other organizations compromised in the incident. The company updated Chrome to block all identified unauthorized certificates and coordinated with certificate authorities to ensure revocation of the fraudulent credentials issued for Google properties. Google urged other domain owners to monitor certificate transparency logs for unexpected certificate issuance, implement restrictive Certification Authority Authorization DNS records, and avoid relying solely on browser-level protections.

The incident represents a significant security event in the certificate authority ecosystem. While all currently identified unauthorized certificates have been blocked, Google acknowledged it cannot guarantee complete discovery of every affected domain and noted that browser interventions do not reliably protect users of other web browsers. The company confirmed that the incident did not involve compromise of the affected domain owners’ own infrastructure and that certificate authorities complied with established requirements during the issuance process.

Unauthorized certificate incidents have occurred previously, including a 2011 compromise of Dutch certificate authority DigiNotar that resulted in counterfeit certificates for over 200 domains being used in attacks against approximately 300,000 individuals.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI